Question 1
What steps are required to decrypt TLS 1.2 traffic using private keys (RSA) in Wireshark?
Correct Answer:
Import the server’s private key for the certificate in Wireshark, enable TLS decryption, and ensure the traffic uses RSA key exchange (not ECDHE)
Explanation:
When TLS uses RSA key exchange, the server’s private key is the piece that unlocks the session keys needed to decrypt the traffic. The client sends a pre-master secret encrypted with the server’s public key; the server uses its private key to decrypt that secret, and from there both sides derive the master secret and the symmetric keys used to encrypt and decrypt the subsequent records. That’s why providing the server’s private key in Wireshark allows it to reconstruct the session. So the right approach is to import the server’s private key corresponding to the certificate shown in the handshake, in a format Wireshark can read (typically PEM), enable TLS decryption in Wireshark’s settings, and ensure the capture uses RSA key exchange (not ephemeral methods like ECDHE). If the handshake uses an ephemeral key exchange such as ECDHE, the private key alone won’t enable decryption because the session keys aren’t derived from the server’s private key; in that case you’d need a client-side key log or another method to obtain the master secrets. This is why the server private key approach works only for RSA key exchange and not for other key exchange methods.
Question 2
How can you compare throughput or data volume across two captures in Wireshark?
Correct Answer:
Compare Statistics → Summary data, use Protocol Hierarchy or Endpoints, or export to CSV and compare
Explanation:
When you want to compare throughput or data volume between two captures, use Wireshark’s built-in statistics to obtain quantitative metrics and then export those results for side-by-side analysis. The Statistics views provide concrete numbers: Summary gives total bytes and packets (and can show throughput over the capture window), Protocol Hierarchy shows how data is distributed among protocols, and Endpoints reveals how much data each host sent or received. Exporting these statistics to CSV lets you line up the numbers from both captures in a spreadsheet or similar tool, making it easy to see exact differences in totals, distribution, or per-endpoint data. Visually relying on color coding is not precise for comparing volumes, and focusing only on timestamps misses data volume entirely. Inferring differences from a single capture manually is error-prone and wastes effort needed for accurate comparison.
Question 3
During port scanning, what type of information is commonly identified?
Correct Answer:
Addressing, Routing, Version Numbers, Patch Levels, Protocols/Services Running
Explanation:
Port scanning maps a target's reachable surface by probing ports to see what is open and what services respond. The information commonly identified includes how the host is addressed and reachable through the network (addressing and routing), the software running on the host (version numbers and patch levels), and the protocols or services listening on each open port. This combination helps gauge what could be exploitable and what defenses are needed. Other options don’t fit because port scanning doesn’t reveal usernames or passwords, which require authentication breaches or credential harvesting; it doesn’t provide data about the physical environment; and it doesn’t give weather information.
Question 4
Which frames indicate a WPA2 4-way handshake for decryption?
Correct Answer:
EAPOL key frames (the four-message handshake)
Explanation:
The WPA2 4-way handshake is carried inside EAPOL Key frames. These four EAPOL Key frames exchanged between the access point and the client establish the Pairwise Transient Key (PTK) and confirm the encryption keys needed to decrypt the data frames. When you see the sequence of four EAPOL Key frames following authentication, that indicates the handshake is in progress and the keys will be derived for decryption. Other frame types don’t indicate this key negotiation: TLS handshake frames belong to TLS sessions, not Wi→Fi encryption; HTTP requests are application-layer traffic that occurs after decryption; WPA-PSK refers to the authentication method and its frames aren’t the formal four-message handshake that derives the encryption keys.
Question 5
Which expression allows filtering by protocol name rather than a port or IP?
Correct Answer:
http (or any other protocol)
Explanation:
Filtering by protocol name uses the protocol’s identifier (the dissector name) to select packets that Wireshark can recognize as carrying that protocol, regardless of which port or IP they use. So you can filter with http to see all HTTP traffic no matter the source or destination port, or similarly with any other protocol you’re interested in. This is exactly what you want when you’re focusing on the protocol itself rather than the transport details. The other options filter by port numbers, IP addresses, or general frame content. ip.addr narrows traffic by who’s communicating, not by the protocol in use. tcp.port restricts by a specific TCP port, which misses traffic of the same protocol on different ports or traffic from other protocols using that port. frame contains data is a broad check on the frame payload and doesn’t target a specific protocol. Note that if the data is encrypted (like HTTPS), the http dissector may not apply, so the protocol-name filter won’t match those packets until decryption is available.
Question 1
Exam overview

About this Exam

Prepare with the Wireshark Block 5 Practice Exam practice quiz. This question bank includes 10 questions covering wireshark, traffic, port, decryption, and windows. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Wireshark Block 5 Practice Exam

This practice set contains 10 questions from the matching question bank and focuses on wireshark, traffic, port, decryption, and windows. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions